[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (36 articles)

|

// AI-powered summary generated at 12:00

> U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money calls itself Kairos, but...
> Debian php8.4 Critical Memory Corruption DSA-6377-1 CVE-2026-14355
It was discovered that a buffer overflow in the implementation of AES Key Wrap with Padding in the openssl extension of PHP, a widely-used open source general purpose scripting language, could result in memory corruption. For the stable distribution (trixie), this problem has been fixed in
> North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider. "The campaign remains active, and new mali...
> Security Roundup: Apple’s Hide My Email Service Fails to Hide Your Email
Plus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout.
> Confidential computing's core trust mechanism is broken. The fix may not exist
Attested TLS: the handshake that can't prove who's on the other end
> CVE-2026-53223 net: guard timestamp cmsgs to real error queue skbs
Information published.
> FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and securit...
> Australian Cyber Aware – As It Was 2606 – June 2026
Australian Cyber Aware - As It Was 2606 - June 2026. Aggregated listing of Australian and New Zealand cybersecurity, privacy, and AI risks developments identified during May 2026. It includes cybersecurity incidents, regulatory updates, news stories, audit findings, and broader industry development...
> CEVA Logistics
Une cyberattaque a touché un partenaire logistique de De Bijenkorf, entraînant des retards dans les commandes, les retours et les remboursements. Le grand magasin enquête sur la possibilité que les attaquants aient également accédé aux données personnelles des clients. Le grand magasin d'appuie sur...
> Debian OpenVPN Key Denial of Service Advisory DSA-6376-1 CVE-2026-11771
Multiple security vulnerabilities were discovered in OpenVPN, which could result in denial of service. For the stable distribution (trixie), these problems have been fixed in version 2.6.14-1+deb13u3. We recommend that you upgrade your openvpn packages.
> Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras, d...
> Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds
A former EU lawmaker was hacked with Pegasus spyware while investigating its use, according to Citizen Lab. The Citizen Lab published a report documenting one of the more darkly ironic findings in recent surveillance research: former Member of the European Parliament Stelios Kouloglou was repeatedly...
> Ubuntu cifs-utils Important Local Attack Regression USN-8496-2
USN-8496-1 introduced a regression in cifs-utils
> New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code where Anthropic's mos...
> New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, remote access, reco...
> USN-8496-2: cifs-utils regression
USN-8496-1 fixed a vulnerability in cifs-utils. Unfortunately, the fix introduced a regression with Kerberos mounts. This update reverts the security update until a complete fix is available. We apologize for the inconvenience. Original advisory details: It was discovered that cifs-utils incorre...
> NetNut proxy network disrupted, 2 million infected devices cut off
A joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. [...]
> CNIL
La Commission nationale de l'informatique et des libertés (CNIL) a rendu public l'ordre du jour de sa séance plénière du 4 juin 2026. Partie I (avec débats): : * Présentation des résultats de l’enquête « DPO et IA » par des représentants du ministère du Travail (DGEFP) et de l’AFPA ; * Comm...
> IMY - autorité suédoise
L'autorité suédoise a prononcé une réprimande à l'encontre de la police pour un manquement à son obligation d'information des voyageurs dans une zone de contrôle aux frontières, l'information n'étant disponible que sur son site internet sans aucun renvoi sur place.Faits et contexteL'autorité suédois...
> North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" mimic the legit...